CVE-2008-3131
powie psys 0.7.0 Alpha - SQL Injection via chatbox.php showid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3131. PoCs published by DNX.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in pSys v0.7.0 Alpha's chatbox.php due to improper sanitization of the 'showid' parameter. It allows an attacker to extract sensitive data from the database when magic quotes are disabled.
Description
SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in pSys v0.7.0 Alpha's chatbox.php due to improper sanitization of the 'showid' parameter. It allows an attacker to extract sensitive data from the database when magic quotes are disabled.